Impact
External control of a file name or path in the Windows Ancillary Function Driver for WinSock permits an authorized user to manipulate file references that the driver uses, which in turn allows the execution of code with higher privileges. Based on the description, it is inferred that an attacker could craft a path that causes the driver to load a malicious module or configuration file and gain elevated local privileges on the affected system. This is a classic CWE‑73 flaw that compromises confidentiality and integrity of the operating system by turning a local user into a system or administrative user.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including all Server Core installations. Systems are impacted when the Ancillary Function Driver for WinSock is present and exposed to an authorized local actor.
Risk and Exploitability
The CVSS score of 7.8 signifies a high‑severity local privilege escalation. The EPSS score of less than 1 % indicates that current exploitation activity is likely very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker must already possess legitimate access to the machine in order to influence the driver’s file path. Once the attacker succeeds in supplying a crafted path, they can obtain elevated privileges and potentially take complete control of the system.
OpenCVE Enrichment